This claim that eIDAS is an attempt to intercept TLS and spy on citizens has been repeated over and over this week without any basis and I'm getting sick of it. I don't understand why everyone immediately assumes bad faith here when it's much more likely that this is just a botched article written by someone who has not had to deal with the intricacies of the web PKI. Do you seriously think the intent here is to allo…
> Do you seriously think the intent here is to allow, say, Italy to issue a certificate and spying on German citizens? This legislation allows and enables it, regardless of intent.
Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
41–50 of 73 posts
Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#42This claim that eIDAS is an attempt to intercept TLS and spy on citizens has been repeated over and over this week without any basis and I'm getting sick of it. I don't understand why everyone immediately assumes bad faith here when it's much more likely that this is just a botched article written by someone who has not had to deal with the intricacies of the web PKI. Do you seriously think the intent here is to allo…
As in "what's the worst outcome that can come from this piece of legislation, assuming malicious intent from the person wielding this law in the future". If the answer to that is "uh, not good" then the legislation is bad.
Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#43From the perspective of European govs: Why should only US entities (and companies like Cloudflare, Amazon or Google) be allowed to get access to communications content ? It’s very logical that Europe wants to do the same.
European CAs can apply to be included in the root stores, and Europeans can definitely write content-delivery (CDN) and content-parsing (browser) software.
This essentially gives a a free hand to NSA to spy non only on Belgians but also EU Institutions, NATO HQ, SWIFT and many more essential but not very public organizations headquartered in Belgium (ever heard of IPC? ENTSO-E?)
Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#44This claim that eIDAS is an attempt to intercept TLS and spy on citizens has been repeated over and over this week without any basis and I'm getting sick of it. I don't understand why everyone immediately assumes bad faith here when it's much more likely that this is just a botched article written by someone who has not had to deal with the intricacies of the web PKI. Do you seriously think the intent here is to allo…
TLS interception likely was never a seriously intended goal, just a side-effect due to how the law was worded.
Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#45Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#46Problem solved.
Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#47Earlier quoted context omitted.
> Do you seriously think the intent here is to allow, say, Italy to issue a certificate and spying on German citizens? This legislation allows and enables it, regardless of intent.
But that does not mean "Europe ready to intercept, spy..." or "EU Tries To Slip In New Powers To Intercept Encrypted Web..." as these articles are claiming.
That is what this legislation would enable, so this is accurate.
> EU Tries To Slip In New Powers To Intercept Encrypted Web
Again, that is what this legislation would enable, so this is also accurate.
Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#48This is insane, and we should hurry up and prepare the technical ways to ensure we know it if we are served a different cert than everybody else. There's ongoing work on this field, but it is now a priority to have it ready.
It exists and works already: Certificate Transparency logs, HSTS and Cert Pinning are “protecting”. The first may have the side-effect (or intended ?) to inform US companies which websites you are visiting upon addition of new entries though…
CT logs are just, well, logs. They don't do anything to protect you from having your traffic intercepted via maliciously issued certificate. You might learn later (if somebody bothers to check) that it occurred but at that point the damage is already done.
> HSTS
This just says the connection should only be established via HTTPS, nothing more.
> Cert Pinning
Cert pinning has been removed both from Chromium and Firefox.
https://chromestatus.com/feature/5903385005916160
https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Rel...
Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#49We really need to go back to days of police actually going through the trouble of investigating and catching criminals - at least in principle. Now every government security agency dreams of having complete access to the communications of everyone so they don't go through the trouble of doing their job. First UK, now EU. Although I'm generally closer to the EU mentality of trusting the governments more than the corpo…
Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#50Useful other side discussion here: https://news.ycombinator.com/item?id=38187479 Important to note is that the main thing everyone is up in arms about, the TLS/HTTPS certificate stuff, already got adjusted after browser makers complained about it; browser makers aren't mandated to trust any certificates for internet traffic and DNS resolution. The only real problem left is QWACs in general being a part of the propose…
See: